CVE Vulnerabilities

CVE-2004-2182

Improper Authentication

Published: Dec 31, 2004 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Jrun Macromedia 4.0 (including) 4.0 (including)
Jrun Macromedia 4.0-sp1 (including) 4.0-sp1 (including)
Jrun Macromedia 4.0-sp1a (including) 4.0-sp1a (including)
Jrun Macromedia 4.0_build_61650 (including) 4.0_build_61650 (including)

Potential Mitigations

References